PT-2022-14860 · Micodus · Micodus Mv720

Dan Dahlberg

+2

·

Published

2022-07-20

·

Updated

2022-09-07

·

CVE-2022-2107

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MiCODUS MV720 GPS tracker (affected versions not specified)
Description The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-2107

Affected Products

Micodus Mv720